uc-cdis / peregrine

GraphQL search API service
Apache License 2.0
11 stars 9 forks source link

chore(deps): [security] bump urllib3 from 1.24.1 to 1.24.2 #149

Closed dependabot-preview[bot] closed 4 years ago

dependabot-preview[bot] commented 4 years ago

Bumps urllib3 from 1.24.1 to 1.24.2. This update includes a security fix.

Vulnerabilities fixed *Sourced from The GitHub Security Advisory Database.* > **High severity vulnerability that affects urllib3** > The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument. > > Affected versions: < 1.24.2
Changelog *Sourced from [urllib3's changelog](https://github.com/urllib3/urllib3/blob/master/CHANGES.rst).* > 1.24.2 (2019-04-17) > =================== > > - Don't load system certificates by default when any other `ca_certs`, `ca_certs_dir` or `ssl_context` parameters are specified. > - Remove Authorization header regardless of case when redirecting to cross-site. (Issue [#1510](https://github-redirect.dependabot.com/urllib3/urllib3/issues/1510)) > - Add support for IPv6 addresses in subjectAltName section of certificates. (Issue [#1269](https://github-redirect.dependabot.com/urllib3/urllib3/issues/1269))
Commits - [`1efadf4`](https://github.com/urllib3/urllib3/commit/1efadf43dc63317cd9eaa3e0fdb9e05ab07254b1) Release 1.24.2 ([#1564](https://github-redirect.dependabot.com/urllib3/urllib3/issues/1564)) - See full diff in [compare view](https://github.com/urllib3/urllib3/compare/1.24.1...1.24.2)


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in the `.dependabot/config.yml` file in this repo: - Update frequency - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired)
dependabot-preview[bot] commented 4 years ago

The following labels could not be found: dependencies.

PlanXCyborg commented 4 years ago

Jenkins Build 1 : time taken 41 min Check the https://jenkins.planx-pla.net/job/Performance%20tests%20for%20uc-cdis/job/peregrine/job/PR-149/1/display/redirect

Test results: Passed: 109, Failed: 0, Skipped: 0

Test Time (PR) Time (master) Diff
@ExportPerformanceTests @Performance: Export all nodes of type: aliquot 0.585 0.245 0.34
@ExportPerformanceTests @Performance: Export all nodes of type: case 0.307 0.232 0.08
@ExportPerformanceTests @Performance: Export all nodes of type: experiment 0.395 0.45 -0.05
@ExportPerformanceTests @Performance: Export all nodes of type: program 0.283 0.051 0.23
@ExportPerformanceTests @Performance: Export all nodes of type: project 0.094 0.042 0.05
@ExportPerformanceTests @Performance: Export all nodes of type: read_group 0.715 0.524 0.19
@ExportPerformanceTests @Performance: Export all nodes of type: read_group_qc 0.192 0.105 0.09
@ExportPerformanceTests @Performance: Export all nodes of type: sample 0.794 0.459 0.34
@ExportPerformanceTests @Performance: Exporting a record by ID on nodes of type: aliquot 0.394 0.234 0.16
@ExportPerformanceTests @Performance: Exporting a record by ID on nodes of type: experiment 0.332 0.253 0.08
@ExportPerformanceTests @Performance: Exporting a record by ID on nodes of type: read_group 0.288 0.068 0.22
@ExportPerformanceTests @Performance: Exporting a record by ID on nodes of type: read_group_qc 0.192 0.06 0.13
@ExportPerformanceTests @Performance: Exporting a record by ID on nodes of type: sample 0.183 0.096 0.09
@QueryPerformanceTests @Performance: Executing bottomUp query # 0 0.696 0.627 0.07
@QueryPerformanceTests @Performance: Executing bottomUp query # 1 0.695 0.642 0.05
@QueryPerformanceTests @Performance: Executing bottomUp query # 3 0.691 0.504 0.19
@QueryPerformanceTests @Performance: Executing bottomUp query # 4 0.496 0.344 0.15
@QueryPerformanceTests @Performance: Executing bottomUp query # 5 0.595 0.29 0.31
@QueryPerformanceTests @Performance: Executing bottomUp query # 6 0.318 0.195 0.12
@QueryPerformanceTests @Performance: Executing bottomUp query # 7 0.181 0.128 0.05
@QueryPerformanceTests @Performance: Executing topDown query # 0 0.185 0.145 0.04
@QueryPerformanceTests @Performance: Executing topDown query # 1 0.108 0.128 -0.02
@QueryPerformanceTests @Performance: Executing topDown query # 2 0.203 0.146 0.06
@QueryPerformanceTests @Performance: Executing topDown query # 3 0.294 0.268 0.03
@QueryPerformanceTests @Performance: Executing topDown query # 4 0.298 0.27 0.03
@QueryPerformanceTests @Performance: Executing topDown query # 5 0.471 0.367 0.10
@QueryPerformanceTests @Performance: Executing topDown query # 6 0.505 0.472 0.03
@QueryPerformanceTests @Performance: Executing topDown query # 7 0.618 0.473 0.14
@SubmissionPerformanceTests @Performance: Submission acknowledgement 10 0.418 0.632 -0.21
@SubmissionPerformanceTests @Performance: Submission acknowledgement 100 3.32 3.153 0.17
@SubmissionPerformanceTests @Performance: Submission aligned_reads_index 10 2.199 2.328 -0.13
@SubmissionPerformanceTests @Performance: Submission aliquot 10 0.446 0.536 -0.09
@SubmissionPerformanceTests @Performance: Submission aliquot 100 3.341 3.519 -0.18
@SubmissionPerformanceTests @Performance: Submission case 100 3.143 3.605 -0.46
@SubmissionPerformanceTests @Performance: Submission clinical_test 10 0.53 0.624 -0.09
@SubmissionPerformanceTests @Performance: Submission core_metadata_collection 10 0.663 0.722 -0.06
@SubmissionPerformanceTests @Performance: Submission core_metadata_collection 100 3.155 3.415 -0.26
@SubmissionPerformanceTests @Performance: Submission demographic 100 3.474 3.785 -0.31
@SubmissionPerformanceTests @Performance: Submission diagnosis 10 0.515 0.576 -0.06
@SubmissionPerformanceTests @Performance: Submission diagnosis 100 3.896 4.142 -0.25
@SubmissionPerformanceTests @Performance: Submission diagnosis 1000 36.019 39.099 -3.08
@SubmissionPerformanceTests @Performance: Submission experiment 10 0.703 0.592 0.11
@SubmissionPerformanceTests @Performance: Submission experiment 100 3.138 3.46 -0.32
@SubmissionPerformanceTests @Performance: Submission experiment 1000 33.427 36.021 -2.59
@SubmissionPerformanceTests @Performance: Submission experimental_metadata 10 2.244 2.128 0.12
@SubmissionPerformanceTests @Performance: Submission exposure 100 3.371 4.281 -0.91
@SubmissionPerformanceTests @Performance: Submission family_history 10 0.446 0.601 -0.16
@SubmissionPerformanceTests @Performance: Submission family_history 100 3.089 6.069 -2.98
@SubmissionPerformanceTests @Performance: Submission keyword 10 0.423 0.484 -0.06
@SubmissionPerformanceTests @Performance: Submission keyword 100 3.539 3.94 -0.40
@SubmissionPerformanceTests @Performance: Submission keyword 1000 35.716 32.74 2.98
@SubmissionPerformanceTests @Performance: Submission publication 10 0.442 0.689 -0.25
@SubmissionPerformanceTests @Performance: Submission publication 100 5.789 3.494 2.30
@SubmissionPerformanceTests @Performance: Submission publication 1000 31.066 33.538 -2.47
@SubmissionPerformanceTests @Performance: Submission read_group 10 0.508 0.682 -0.17
@SubmissionPerformanceTests @Performance: Submission read_group 100 3.377 3.773 -0.40
@SubmissionPerformanceTests @Performance: Submission read_group_qc 100 5.063 5.54 -0.48
@SubmissionPerformanceTests @Performance: Submission sample 10 0.647 0.501 0.15
@SubmissionPerformanceTests @Performance: Submission sample 100 3.412 3.809 -0.40
@SubmissionPerformanceTests @Performance: Submission slide 10 0.444 0.544 -0.10
@SubmissionPerformanceTests @Performance: Submission slide 100 3.596 3.419 0.18
@SubmissionPerformanceTests @Performance: Submission slide 1000 33.213 35.347 -2.13
@SubmissionPerformanceTests @Performance: Submission slide_count 10 0.43 0.462 -0.03
@SubmissionPerformanceTests @Performance: Submission slide_image 10 2.018 2.171 -0.15
@SubmissionPerformanceTests @Performance: Submission slide_image 100 21.157 22.494 -1.34
@SubmissionPerformanceTests @Performance: Submission submitted_aligned_reads 10 2.196 2.313 -0.12
@SubmissionPerformanceTests @Performance: Submission submitted_copy_number 10 2.036 2.25 -0.21
@SubmissionPerformanceTests @Performance: Submission submitted_unaligned_reads 10 2.238 2.131 0.11
@SubmissionPerformanceTests @Performance: Submission treatment 10 0.496 0.472 0.02
@SubmissionPerformanceTests @Performance: Submission treatment 100 3.876 3.506 0.37
@SubmissionPerformanceTests @Performance: Submission treatment 1000 32.407 36.2 -3.79
dependabot-preview[bot] commented 4 years ago

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.